Thats what i was looking for not if you were going to patch it! If they were!<br><br><div><span class="gmail_quote">On 2/5/07, <b class="gmail_sendername">Ben Bucksch</b> &lt;<a href="mailto:news@bucksch.org">news@bucksch.org
</a>&gt; wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">No, we never patch bugs. Where would this lead us? Only commies taking over!
<br><br>Tracked in bug 369390.<br><br>James Matthews wrote:<br>&gt; Do you think it will be patched??<br>&gt;<br>&gt; On 2/5/07, *Michal Zalewski* &lt;<a href="mailto:lcamtuf@dione.ids.pl">lcamtuf@dione.ids.pl</a><br>&gt; &lt;mailto:
<a href="mailto:lcamtuf@dione.ids.pl">lcamtuf@dione.ids.pl</a>&gt;&gt; wrote:<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; On Mon, 5 Feb 2007, pdp (architect) wrote:<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; &gt; You may as well use a QuickTime .mov/.qtl or a PDF document to
<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; open a<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; &gt; file:// link . I think it is easier.<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Sure. You can probably have a file:// link in Open Office / MS Office<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; documents as well; but these all rely on external components, and
<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; as such,<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; attacks could be shrugged off as a weakness in these apps (and there&#39;s<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; some truth to this).<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Browser authors know better, and they disallow file:// URLs from the
<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Internet ever since Javascript became so powerful; this case<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; managed to<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; slip through, so I thought it&#39;s a neat example, in conjunction with<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; deterministic temporary files.
<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; /mz<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; _______________________________________________<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Full-Disclosure - We believe in it.<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">
http://lists.grok.org.uk/full-disclosure-charter.html</a><br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Hosted and sponsored by Secunia - <a href="http://secunia.com/">http://secunia.com/</a><br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt; --<br>&gt; <a href="http://www.goldwatches.com">
http://www.goldwatches.com</a><br>&gt; <a href="http://www.wazoozle.com">http://www.wazoozle.com</a><br>&gt; ------------------------------------------------------------------------<br>&gt;<br>&gt; _______________________________________________
<br>&gt; Full-Disclosure - We believe in it.<br>&gt; Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>&gt; Hosted and sponsored by Secunia - 
<a href="http://secunia.com/">http://secunia.com/</a><br><br>_______________________________________________<br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">
http://lists.grok.org.uk/full-disclosure-charter.html</a><br>Hosted and sponsored by Secunia - <a href="http://secunia.com/">http://secunia.com/</a><br></blockquote></div><br><br clear="all"><br>-- <br><a href="http://www.goldwatches.com">
http://www.goldwatches.com</a><br><a href="http://www.wazoozle.com">http://www.wazoozle.com</a>